OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti] RE: Questions based on iSIGHT Sample


This is, I believe how you would represent the below, except using our current in-process patterning proposal that Paul is referring to - presuming I copy / pasted it accurately.

As you can see, in my opinion it is much more compact, and easier to read / comprehend, while being easily parseable through usage of a grammar.

Note that the fact that you are looking for a file *within* the email is implicit through usage of the WITH keyword as opposed to the AND keyboard.

"indicators": [
{
"pattern":"
(
email-message-object:header/subject = 'Facturation Octobre 2015 et Rachat'
)
WITH
(
file-object:file_system_properties/file_name = 'facture-97620236.doc' AND
(
( file-object:hashes/hash_type = 'MD5' AND file-object:hashes/hash_value = '28e2d98623771f2176f672e61ee3f423' ) OR
( file-object:hashes/hash_type = 'MD5' AND file-object:hashes/hash_value = '81c321493c91e5413538ad90f44f1740' ) OR
( file-object:hashes/hash_type = 'MD5' AND file-object:hashes/hash_value = '7ef4316439c03814d8d2b0329a6538e4' ) OR
( file-object:hashes/hash_type = 'MD5' AND file-object:hashes/hash_value = '098ad1f5ddd71633f7385022f374a8d0' ) OR
( file-object:hashes/hash_type = 'MD5' AND file-object:hashes/hash_value = '0483a670833dbaddb3a310225485b66f' ) OR
( file-object:hashes/hash_type = 'SHA1' AND file-object:hashes/hash_value = '1744dfd6a08e6a6606a1143880f0a3280d89e126' ) OR
( file-object:hashes/hash_type = 'SHA256' AND file-object:hashes/hash_value = 'c1a3f0aa7df620b20edffb483203d661bdb7994f22baa3a443832acf3ecedfad' )
)
)
"
}
]

-
Jason Keirstead
STSM, Product Architect, Security Intelligence, IBM Security Systems
www.ibm.com/security | www.securityintelligence.com

Without data, all you are is just another person with an opinion - Unknown


Inactive hide details for Paul Patrick ---03/28/2016 07:18:44 PM---Alex, What is there isn't the best way to do it and I think Paul Patrick ---03/28/2016 07:18:44 PM---Alex, What is there isn't the best way to do it and I think a bunch of us are aware of that. I've sh

From: Paul Patrick <ppatrick@isightpartners.com>
To: "Foley, Alexander - GIS" <alexander.foley@bankofamerica.com>
Cc: "cti@lists.oasis-open.org" <cti@lists.oasis-open.org>
Date: 03/28/2016 07:18 PM
Subject: Re: [cti] RE: Questions based on iSIGHT Sample
Sent by: <cti@lists.oasis-open.org>





Alex,

What is there isn't the best way to do it and I think a bunch of us are aware of that. I've shown some folks the current thinking around patterns and they like it so much better. Hopefully we're getting close enough that I can update the report with the latest proposal

Paul

Sent from my iPhone


On Mar 28, 2016, at 5:48 PM, Foley, Alexander - GIS <
alexander.foley@bankofamerica.com> wrote:



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]